Description
A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

A remote attacker can exploit a SQL injection flaw in the login1.php page of itsourcecode Online Admission System Project 1.0 by supplying a specially crafted User parameter. The vulnerability arises from inadequate validation of this input, allowing arbitrary SQL statements to be executed against the backend database. If the injection succeeds, an attacker could bypass authentication, retrieve or modify user credentials and other sensitive data, and potentially gain further access to the application. The weakness is associated with CWE‑74 and CWE‑89 and represents a standard SQL injection scenario with potential confidentiality, integrity, and availability impact for the affected system.

Affected Systems

The affected product is itsourcecode's Online Admission System Project version 1.0. The flaw resides in the /admin/login1.php file, and the issue is tied to the user parameter that is passed into SQL queries without proper sanitization. Organizations running this version should assume the application is vulnerable until a patch or remediation is applied. No other versions are explicitly documented as affected in the available information.

Risk and Exploitability

The CVSS score of 6.9 indicates a high level of risk under the base metric set, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the attack can be initiated remotely over an HTTP interface, the probability of exploitation could be significant if the application is exposed to the internet and no additional mitigations are in place. Given that a public exploit is already documented, administrators should treat this as a medium to high priority risk and act promptly to secure the system.

Generated by OpenCVE AI on October 5, 2026 at 09:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the application to the latest version from itsourcecode that addresses input sanitization in login1.php.
  • Modify the login1.php script to use parameterized SQL statements or otherwise escape user input before including it in queries.
  • Limit the database account used by the application to only the permissions required for authentication and monitor database logs for suspicious activity.

Generated by OpenCVE AI on October 5, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Title itsourcecode Online Admission System Project login1.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Admission System Project
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_admission_system_project:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Admission System Project
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Admission System Project
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T08:15:13.774Z

Reserved: 2026-10-04T17:56:41.076Z

Link: CVE-2026-105253

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:11.753

Modified: 2026-10-05T09:17:11.753

Link: CVE-2026-105253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:30:10Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')